⌁ CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code

September 5, 2026

Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code Ravie LakshmananSep 05, 2026Vulnerability / Server Security Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host," Broadcom said in an alert. The tech giant credited @h4urek, @cameudis, and Stan S for discovering the issue. Also patched by Broadcom…

CVEs: CVE-2026-59346, CVE-2026-59347, CVE-2026-59309, CVE-2026-59310